Today’s cyberattacks on enterprises are persistent and advanced—no enterprise is 100 percent secure. It is no longer sufficient to only focus on prevention and detection. Enterprises need to consider cybersecurity from this standpoint and be part of an integrated and holistic, enterprise-wide approach.
With cyber incidents increasing, it is important for businesses to become cyberresilient; anticipating, withstanding and recovering from attacks. At the rapid evolving rate of cybercrime, it is more than an issue for the IT department—it is an issue for everyone in the business. The National Association of Corporate Directors, for example, encourages boards of directors to have a role ensuring that management is fully engaged in developing response plans .
The engagement must include understanding and prioritizing stakeholder needs, identifying the core business processes and understanding the potential impact of a cyberincident on the business. To help businesses approach cyber security holistically, ISACA recently released a new guide, The Cyberresilient Enterprise: What the Board of Directors Needs to Ask.
The 19 key questions boards should ask include:
Is sufficient attention given to the ability to defend against intrusions as well as the ability to recover and restore essential functions and services?
Is the board routinely informed about the potential material operational risk and risk mitigation strategies as well as incidents that could impact the brand?
To what extent have essential services and functions been identified and programs implemented to provide for their resilience in the event of a disruption or cyberincident?
As the paper points out, board members need to evaluate the operational risk inherent in today’s digital business and direct management so the enterprise is more than just protected—it is resilient. If boards dig deep and receive appropriate answers to these questions, they can help the resiliency of the enterprise as it continues its mission of value creation.
Ron Hale, Ph.D., CISM Chief Knowledge Officer of ISACA
For the full list of questions and to download The Cyberresilient Enterprise: What the Board of Directors Needs to Ask, visitwww.isaca.org/cyberresilient.
Yoga is a popular science and art of well-being. Its benefits range from as modest as being helpful for fixing specific ailments or disorders to transforming one’s body-mind communion to attain a state of eternal exhilaration and union, by aligning oneself with the world and nature.
Consider applying the concept of yoga to enterprise IT—if business is seen as the body, information surely is its mind. And, the right information at the right time with the right person can make the difference between exceptional success and dooming failure.
Given that we now inhabit an increasingly connected digital world, there is less disagreement on the ever more critical dependence on IT. Businesses clearly recognise the strategic nature of IT, but also often find themselves entangled in a range of IT pains and disillusioning disorders. Such issues include IT operational issues, IT project failures, cost over-runs and data breaches and a stagnating, or, at the other extreme, hyper IT that keeps costing resources and attention, without synchronised business deliveries. Baffled with finding the answers, organisations increasingly tend to find themselves at a loss when it comes to ascertaining the right approach to making IT work optimally for business.
COBIT 5 is a framework for enterprise IT governance that provides compelling reasons for a shift in an enterprise’s approach to management and governance of enterprise IT. Built on five key principles, many of COBIT 5’s principles resonate the yogic thinking, such as starting with the need to focus on stakeholders’ needs, covering the enterprise end to end, adopting a single aligned framework with a holistic approach and separating governance from management.
Many organisations suffering from impulsive or chronic IT operational and management issues have found solutions from COBIT 5 to effectively alleviate their burning pain points. But then there are the larger and often constipated IT governance questions of finding sustainable ways to make enterprise IT naturally meet strategic, compliance and reporting needs. Profound IT governance issues include chronic disorders, such as IT management deadlocks, certification fatigue, and goal disconnects between the board, the executive level and underlying operational layers. Also, governance issues can include, as I mentioned previously, either a stagnating or disintegrating IT or hyper IT.
As with yoga, there is emerging realisation that in the digital connected world, there are fewer chances for a business entity to achieve sustainable growth, unless it clearly recognises how it can make a difference to the world at large. There is a need for moving from an inside-out-focused thinking to one that is outside-in-driven. The focus on the goal needs to clearly shift from chasing profits and numbers to being relevant and making a difference to stakeholders, and aligning enterprise IT capabilities accordingly.
As a first step, take a cue from the transformational aspects of yoga that first looks at transforming the fundamental thinking through deeper introspection on questions such as, “Why do I exist?” Enterprise leadership could apply this question in their capacity as stakeholder representatives. That would help trigger a whole business-IT (body-mind) transformation at every layer. And, when an organisation experiences such a transformed realisation, suddenly it tends to be unexpectedly rewarded with answers and solutions that appear to be so simple—as if they were always there—and loaded with eternal benefits for all stakeholders.
To achieve this, an organisation would need to look within. It needs to challenge its approach at every layer of enterprise IT to see if what is being done has the goal of stakeholder value maximisation in mind, rather than the narrow perspective of maximising its own profits and numbers. All of this means experiencing information and IT capability empowerment at every level—not for mere IT sake but for governance sake.
Much like there is no one form of yoga that fits all, there is also no one COBIT 5 approach that will fit every organisation. Every organisation will, according to its near- and long-term goals, need to churn through the COBIT 5 guidance to concoct its own IT governance framework that aligns with its business and enterprise IT needs. Besides, an IT governance approach founded on COBIT 5 not only co-exists very well, but also inspires greater alignment with various standards that an enterprise considers as relevant.
If approached and practiced diligently enterprise-wide, every organisation could experience several rewards that include quality information-driven decisions, maximising stakeholder value from IT enabled investments, IT operational excellence, and IT risk and resource optimisation.
Hence, it may not be out of place to believe that to survive and sustain in the emerging global cyber economy, enterprises could do well to move from their narrow pursuit of IT happiness to a broader expression of enterprise information-aligned IT joy!
Vittal Raj,CISA, CISM, CGEIT, CRISC, CFE, CIA, CISSP, FCA, COBIT 5 Foundation Accredited Trainer Founder and partner of M/s. Kumar & Raj, and Director at Pristine Consulting Private Limited
For Donnie Grimes, (ISC)² Global Academic Program (GAP) instructor and vice president of information systems and creator of the Master’s program in cybersecurity for the University of the Cumberlands, based in Williamsburg, Kentucky, breaches know no boundaries – and neither should cybersecurity education.
A GAP member since 2014, the University has historically served people from the Appalachia area; and until 2014, had no cybersecurity offering. Over the past 10-15 years, however, its sphere of influence has increased, with thriving graduate programs and students representing 58 different countries and most U.S. states. With a 40-year stint as a two-year school, Cumberlands is now a four-year college with 5,500 students. Cumberlands is one of the largest online schools in Kentucky, with an online population of approximately 4,000.
In 2012, Cumberlands tasked Grimes with developing the graduate cybersecurity curriculum for the University. As part of this process, he researched hundreds of different programs but couldn’t find many in cybersecurity, let alone those that adequately prepared students to enter the field. He found many schools that offered Master’s programs, but he believed they were really just glorified computer science programs. They included classes on data structures and programming, and just tacked one or two classes on at the end of the program and called them a “Master’s” in cybersecurity.
His vision for the Cumberlands was to create a Master’s program that was more in line with certification programs, such as the CISSP®, that exposes students to real-world concepts and prepares them for the pursuit of continual learning, which is essential for success in the field. Grimes designed the curriculum around the CISSP CBK®, with each course based upon a different CISSP CBK domain. He believes this approach provides a great foundation for students and ensures well-rounded graduates.
He worked to get the University and the information security program accredited through the Commission on Colleges of the Southern Association of Colleges and Schools (SACS). While there have been no graduates yet, there are 120 students enrolled in the program, including CIOs from a wide variety of industries. Their feedback has been very positive, and Grimes sees this compliment from professionals working in the field as the best they could receive.
Grimes implemented a process to review modifications to the CBK domains so they can keep up with industry fluctuations. Says Grimes, “We are not afraid of change. Our goal is to keep the program flexible enough to accommodate the realities of a dynamic industry.”
In discussing why the Cumberlands became a GAP school, Grimes comments that it was a “…value-add for our program and a natural fit because our curriculum was already aligned with the CISSP. We were already encouraging our graduates to sit for the CISSP exam because it validates their core knowledge. Becoming a GAP school streamlines the process and helps us keep our curriculum aligned with real-world concepts they can apply not only to their education process, but that will contribute to their success in the field.”
So what’s next for this rapidly growing school? Grimes would like to create courses that train future cybersecurity leaders and to see the University reach students in more parts of the world. The University also plans to launch a PhD program in information security this year. The University is currently working with the NSA and DHS to become a National Center of Academic Excellence. He reflected, “Our extensive online program means that students’ educational opportunities are not limited by their physical location. Breaches know no boundaries, and as an educational institution, we shouldn’t either. Regional colleges have an important role in stemming the cybersecurity skills shortage, and we should take advantage of virtual learning systems to improve the cybersecurity situation globally.”
Managers keen to avoid business interruption are delaying crucial software updates to industrial control systems. But with viruses like Stuxnet at large, this leaves organisations vulnerable says Del Rodillas.
One major reason why many industrial control systems (ICS) are highly susceptible to cyberattacks is that their software patching and anti-malware update cycles are infrequent – if they’re even happening at all.
Adding to this weakness is the growing presence of widely used Commercial Off-the-Shelf (COTS) systems whose universe of vulnerabilities and malware is constantly and rapidly expanding. As seen in examples such as the Stuxnet and Energetic Bear attacks, these payloads can be leveraged in sophisticated cyberattacks that, if successful, could severely impact not only process availability but also safety. Let’s examine some of the ways to stay secure even in this difficult environment.
In my experience, it’s not that ICS security professionals don’t understand that patching is necessary and that systems are at risk of being compromised. Rather, it’s how the cumbersome process of ICS patching affects their main priority, which is high uptime.
Keeping the system available and running properly is critical whether the organisation is producing oil, transporting electricity or some other intensive process.
Patching in ICS to install software updates that fix vulnerabilities or to install the latest exploit/malware signatures usually requires stopping that process. With so much pressure on administrators to keep system uptime high, they often delay patching for months, or longer, to maximize production.
“It’s not that ICS security professionals don’t understand that patching is necessary and that systems are at risk of being compromised. Rather, it’s how the cumbersome process of ICS patching affects their main priority, which is high uptime.”
In some cases, the nature of the physical process dictates the patching cycles, some of which can span years. There is also a risk that the patches may cause a system to behave in undesired ways, adding even more hesitancy to patch. It’s for these reasons that ICS patching must be done methodically. But during this window of being unpatched, the systems are highly vulnerable to known threats as well as zero-day threats that have not yet been discovered in the wild.
While security vendors do their best to ensure that new software updates do not cause any issues to systems, they may not have tested all scenarios – some of which may cause performance issues or system crashes once deployed in production.
These disruptions cause big problems in industrial automation environments where even temporary loss of visibility and control at the Human Machine Interface or automation server level could lead to substantial production losses and even compromise worker or consumer safety.
The quality assurance process is made more difficult by the fact that personnel don’t always see exploitable software vulnerabilities or new software feature as compelling enough events to “mess” with a system that is working just fine. The old adage of “if it ain’t broke don’t fix it” often reigns supreme in this environment. Too often operational technology personnel believe that they sufficiently isolated for these vulnerabilities to be exploitable. But Stuxnet, which attacked an air-gapped ICS environment, is just one example of this fallacy.
There are still other challenges. Variants of older malware such as Conficker or Slammer could be accidentally released into the ICS causing various levels of loss of visibility and/or control to the process from account lockout, HMI software non-responsiveness, or the debilitating “blue-screen of death” in which machines are rendered useless.
It’s important to note that in some cases, the ICS software may not be patchable at all. For example, there are some ICSes in the middle of their lifecycle that use operating systems such as Windows XP and Windows Server, neither of which is still actively supported. Given that the average lifecycle for an ICS is more than a decade, it could be years before asset owners can deploy newer, supported operating systems. An older system is therefore susceptible to both known and unknown threats – and the known threats won’t be patched.
A good cybersecurity strategy in ICS must include both a systematic approach to patch management and compensating cybersecurity controls when patching is not an option. Patch management increases cybersecurity through the installation of patches that resolve bugs, operability, reliability, and cybersecurity vulnerabilities. The ISA-TR62443‑2‑3 technical report, developed by the ISA 99 Working Group 6 in collaboration with IEC 62443 standards body, addresses the patch management aspect of ICS cyber security.
Here are five factors to consider when choosing ICS security:
Reduce the attack surface – Make sure that the technology you select gives you granular controls at the application, user, and content levels. Also ensure these controls are contextually tied versus residing on separate disjointed network security devices. This leads not only to better administrative efficiency but also accuracy of the policies that you implement.
Stop the propagation of known threats – Select a segmentation gateway that has native threat prevention capabilities to stop known malware and exploits from propagating in your network. This serves as your first level of defense for protecting unpatched systems from threats whether specific to ICS-products or more general business software and operating systems. Having this capability natively in the gateway instead of implemented as a separate, add-on device is important to ensure once again that there is shared context with the application/protocol and user information collected by the gateway.
Deploy sandboxing technology to stop zero-day threats – Advanced attackers will use zero-day malware to compromise your network. Network sandboxing technologies that isolate suspicious payloads into a cloud-based environment, analyze them to determine their nature (malicious/benign), and send protections back to the user, are invaluable in terms of preventing zero day threats from propagating into networks. Make sure that this capability is native to the access control device so that there is a closed loop for protection, versus just serving as a detection-only device.
Prevent zero-day attacks to the endpoint – If the threat manages to bypass network security or is implemented locally at the endpoint, it is important that any attempts to compromise the system, whether using exploits or malware, are stopped. Detection-only technologies are not enough; these attacks must be prevented. The risks are too high in critical infrastructure applications to allow threats to successfully execute. They must be prevented. Newer technologies are available which rather than trying to stop exploits and malware using known threat signatures (hashes, strings, behaviors), stops the underlying techniques employed by these threats – halting even zero-day attacks to unpatched systems.
Select a platform vs. point solutions – Integrating point solutions for network security, sandboxing and endpoint security leads to information silos, slow forensics, high administrative overhead and security gaps. When selecting a security architecture, make sure the components you pick work together as a platform. Application/Content firewalls, IPS, and URL filter functionality should be integrated into the access control device. Furthermore, the access control device should make use of the output of the cloud sandboxing technology to ensure a closed loop in terms of stopping zero-day threats. The endpoint security should also take advantage of the threat intelligence provided by the cloud to ensure even stronger security posture than if the endpoint security was working in isolation.
Internal audit has recently been called “the new pillar of senior management” because it is a key element in the structure of the company, contributing to the strength of internal control, risk management and corporate governance. COBIT 5, the last ISACA’s framework for the governance and management of enterprise IT, can help the internal audit function to be this pillar in many ways.
COBIT 5 is based on the assumption that companies exist to create value for their stakeholders. If companies exist for this purpose, auditors have to assess and report to the board of directors on whether benefits are delivered and risk and resources are optimized.
Internal auditors can use COBIT5 to set and prioritise specific enterprise goals and IT-related goals.
To be the pillar of senior management, auditors have to consider:
Stakeholder value of business investments: Auditors should assess the alignment of IT with business strategy; executive management commitment regarding IT-related decisions; the optimization of IT assets, resources and capabilities; and the realization of benefits from IT.
Management of business risk to protect assets: Auditors should assess how well IT-related business risk is managed and how well information, processing infrastructure and applications are secured.
Compliance with external laws and regulations and internal policies: Auditors should assess IT compliance with legal and internal requirements and IT support for business compliance with these requirements.
Optimization of business process functionality: One of the objectives of internal controls is improving the business process functionality. Internal auditors should assess how well applications and technology are integrated into the business process to enable and support them.
If these goals are considered for both enterprise and internal auditors, senior management will have to consider them as an important resource— as “a new pillar.”